Master the fundamental concepts of binary exploitation through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksA stack canary is a randomly chosen value placed on the stack between local variables and the saved return address. Before the function returns, the canary is checked. If it changed, a buffer overflow occurred and the program aborts via __stack_chk_fail().
The compiler inserts checks automatically with -fstack-protector:
fs:0x28 on x64)__stack_chk_fail() and terminates the processCanary types:
strcpy)You will simulate the canary check itself: given the canary value and an overflow payload, determine how many canary bytes survive, find the first byte position where the payload disagrees with the canary, and decide whether __stack_chk_fail() fires. This includes the attacker's view: a payload that reproduces the exact canary bytes (the canary-leak bypass) sails through the check.
Attackers leak the canary value through format string bugs or partial reads, then include the correct canary in their overflow payload to pass the check. The canary sits in a thread-local slot at fs:0x28 on Linux x64, copied onto the stack at function entry. Building with -fstack-protector-all protects every function, not just those with char arrays, at a small performance cost.
Write a C program that reads a canary (8 bytes, hex), a byte offset where the canary sits, and a payload (hex) from stdin, and simulates the stack-protector check.
Requirements:
Success Criteria: